{"api_version":"1","generated_at":"2026-08-15T05:26:42+00:00","cve":"CVE-2026-68201","urls":{"html":"https://cve.report/CVE-2026-68201","api":"https://cve.report/api/cve/CVE-2026-68201.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68201","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68201"},"summary":{"title":"ALSA: timer: drain a slave's callback before its master detaches it","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: drain a slave's callback before its master detaches it\n\nsnd_timer_close_locked() drains the closing instance's own in-flight\ncallback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a\nmaster instance is closed, remove_slave_links() clears each slave's\n->timer; the slave's own close then reads timer == NULL and takes the\nbranch that skips the drain entirely (snd_timer_stop_slave() also no-ops\non a NULL timer). So a slave whose callback is still running when the\nmaster is closed is freed underneath the live callback, leading to\nuse-after-free.\n\nDrain the slaves too before remove_slave_links() severs them.\nsnd_timer_stop() has already taken this instance off the active list, so\nno new slave callback can be queued. Take the slaves off the ack list so\na pending one can't fire either, then wait for any that is already in\nflight.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:07","updated_at":"2026-08-13 23:17:23"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/bdefe1346a8e6b8dc8593406dc2617e985fcbcab","name":"https://git.kernel.org/stable/c/bdefe1346a8e6b8dc8593406dc2617e985fcbcab","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/426c0ff1c433d6030610ad4f9375746dfe931caa","name":"https://git.kernel.org/stable/c/426c0ff1c433d6030610ad4f9375746dfe931caa","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2b298997786876b225cff2446e11a0fa6f602f6d","name":"https://git.kernel.org/stable/c/2b298997786876b225cff2446e11a0fa6f602f6d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0","name":"https://git.kernel.org/stable/c/cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68201","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68201","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 426c0ff1c433d6030610ad4f9375746dfe931caa git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 2b298997786876b225cff2446e11a0fa6f602f6d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 bdefe1346a8e6b8dc8593406dc2617e985fcbcab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.101 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc5 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"68201","cve":"CVE-2026-68201","epss":"0.001700000","percentile":"0.067030000","score_date":"2026-08-14","updated_at":"2026-08-15 00:04:44"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/core/timer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"},{"lessThan":"426c0ff1c433d6030610ad4f9375746dfe931caa","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"},{"lessThan":"2b298997786876b225cff2446e11a0fa6f602f6d","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"},{"lessThan":"bdefe1346a8e6b8dc8593406dc2617e985fcbcab","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/core/timer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.12"},{"lessThan":"6.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.101","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc5","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.101","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc5","versionStartIncluding":"6.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: drain a slave's callback before its master detaches it\n\nsnd_timer_close_locked() drains the closing instance's own in-flight\ncallback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a\nmaster instance is closed, remove_slave_links() clears each slave's\n->timer; the slave's own close then reads timer == NULL and takes the\nbranch that skips the drain entirely (snd_timer_stop_slave() also no-ops\non a NULL timer). So a slave whose callback is still running when the\nmaster is closed is freed underneath the live callback, leading to\nuse-after-free.\n\nDrain the slaves too before remove_slave_links() severs them.\nsnd_timer_stop() has already taken this instance off the active list, so\nno new slave callback can be queued. Take the slaves off the ack list so\na pending one can't fire either, then wait for any that is already in\nflight."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the local ALSA timer character device /dev/snd/timer (open, SNDRV_TIMER_IOCTL_SELECT/START/CREATE/TRIGGER, close) — no remote or network path exists into sound/core/timer.c.\nAC:L - The attacker owns both sides of the race: it creates the master/slave instances, drives callback delivery itself via the userspace-driven timer's SNDRV_TIMER_IOCTL_TRIGGER ioctl, and chooses the close ordering, and can widen the window with many slaves and queued events, so the UAF is reliably reproducible.\nPR:L - No capable() or CAP_* check exists on any part of the path; any local user with access to /dev/snd/timer (normal for desktop/Android audio-group users and sandboxed apps) can create utimers and open master and slave instances.\nUI:N - A single unprivileged process performs all steps — open, select, start, trigger and close — with no action from any other user or victim process required.\nS:U - The corruption is confined to the kernel's own heap and the ALSA timer subsystem; no VM, IOMMU or other security-authority boundary is crossed.\nC:H - The freed snd_timer_instance/snd_timer_user objects can be reclaimed by attacker-sprayed data, and the still-running callback reads and later exposes freed-slab contents through the timer read queue, enabling disclosure of arbitrary kernel heap data.\nI:H - The in-flight callback writes attacker-influenced tread records into the already-freed tqueue and performs list and waitqueue updates on freed memory, giving a controllable use-after-free write usable for heap corruption and control-flow hijack.\nA:H - The use-after-free corrupts slab memory and list pointers, readily producing an oops, list_del corruption BUG or panic that takes down the whole system."}]}],"providerMetadata":{"dateUpdated":"2026-08-13T22:41:40.172Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0"},{"url":"https://git.kernel.org/stable/c/426c0ff1c433d6030610ad4f9375746dfe931caa"},{"url":"https://git.kernel.org/stable/c/2b298997786876b225cff2446e11a0fa6f602f6d"},{"url":"https://git.kernel.org/stable/c/bdefe1346a8e6b8dc8593406dc2617e985fcbcab"}],"title":"ALSA: timer: drain a slave's callback before its master detaches it","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68201","datePublished":"2026-08-10T12:00:20.280Z","dateReserved":"2026-07-30T09:28:09.374Z","dateUpdated":"2026-08-13T22:41:40.172Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:07","lastModifiedDate":"2026-08-13 23:17:23","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68201","Ordinal":"1","Title":"ALSA: timer: drain a slave's callback before its master detaches","CVE":"CVE-2026-68201","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68201","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: drain a slave's callback before its master detaches it\n\nsnd_timer_close_locked() drains the closing instance's own in-flight\ncallback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a\nmaster instance is closed, remove_slave_links() clears each slave's\n->timer; the slave's own close then reads timer == NULL and takes the\nbranch that skips the drain entirely (snd_timer_stop_slave() also no-ops\non a NULL timer). So a slave whose callback is still running when the\nmaster is closed is freed underneath the live callback, leading to\nuse-after-free.\n\nDrain the slaves too before remove_slave_links() severs them.\nsnd_timer_stop() has already taken this instance off the active list, so\nno new slave callback can be queued. Take the slaves off the ack list so\na pending one can't fire either, then wait for any that is already in\nflight.","Type":"Description","Title":"ALSA: timer: drain a slave's callback before its master detaches"}]}}}